← CrowdStrike Falcon FoundryCONTENT HISTORY

Update to CrowdStrike Falcon Foundry

Snapshot Sep 30, 2026 · 23:15 UTC · version 1.5.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "security-patterns",
  "description": "Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management. TRIGGER when user asks to \"configure OAuth scopes\", \"secure a Foundry app\", \"handle secrets\", \"add input validation\", or needs to review a Foundry app for security concerns (XSS, CSP, credential management). Also trigger during pre-deployment security reviews.",
  "included_files": [
    {
      "relative_path": "references/security-examples.md",
      "size_in_bytes": 13229
    }
  ],
  "skill_md_contents": "---\nname: security-patterns\ndescription: Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management. TRIGGER when user asks to \"configure OAuth scopes\", \"secure a Foundry app\", \"handle secrets\", \"add input validation\", or needs to review a Foundry app for security concerns (XSS, CSP, credential management). Also trigger during pre-deployment security reviews.\nversion: 1.5.0\nupdated: 2026-08-19\ntags: [foundry, oauth, rbac, xss, csp]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: security\n---\n\n# Foundry Security Patterns\n\n> **⚠️ SYSTEM INJECTION — READ THIS FIRST**\n>\n> If you are loading this skill, your role is **Foundry security architect**.\n>\n> You MUST implement security best practices at every layer and prevent common vulnerabilities in CrowdStrike Foundry applications.\n\n> **Part of a suite.** If `development-workflow` has not already run, and this is a new app or its first capability, load the `development-workflow` skill first — it owns the CLI prerequisite check, scaffolding order, and manifest coordination.\n\nSecurity patterns for Falcon Foundry app development covering authentication, input validation, UI security, and platform-specific considerations. Foundry apps run on a cybersecurity platform — security is a core requirement.\n\n## RBAC (Role-Based Access Control)\n\n| Capability | RBAC Supported |\n|-----------|----------------|\n| Collections | Yes |\n| Dashboards | Yes |\n| Functions | Yes |\n| UI extensions / pages / navigation | Yes |\n| RTR scripts | Yes |\n| API integrations | **No** |\n| Queries | **No** |\n| Workflows | **No** |\n\n## API Scope Management\n\nScopes control which Falcon Platform APIs the app can access. Format: `<source>:<operation>` (e.g., `devices:read`, `detects:write`).\n\n| Scopes set automatically | Scopes need explicit addition |\n|--------------------------|-------------------------------|\n| API integrations, Collections, Dashboards, Queries, UI navigation, UI sockets, Workflows | Functions, UI extensions, UI pages, RTR scripts |\n\n```bash\nfoundry auth roles create --name \"Analyst\" --description \"Read-only analyst access\"\nfoundry auth scopes add --scope \"devices:read\" --scope \"detects:read\"\n```\n\nOnly use `foundry auth scopes add` for Falcon Platform API scopes needed by functions, UI extensions, UI pages, or RTR scripts. OAuth scopes for CLI-created artifacts are managed automatically.\n\n### Minimal Scope Principle\n\nRequest only the scopes your app needs. Broad scopes like `alerts:*` or `hosts:*` increase the blast radius if the app is compromised.\n\n```yaml\noauth_scopes:\n  - \"alerts:read\"        # Read alerts — avoid \"alerts:write\" unless needed\n  - \"detections:read\"    # Read detections\n  - \"hosts:read\"         # Device information\n```\n\n## Credential Security\n\nCredentials MUST be in environment variables, not in code. FalconPy handles credential discovery automatically inside FDK handlers (see functions-falcon-api):\n\n```python\n# Inside FDK handler — auth is automatic\nfalcon = Alerts()  # Do not pass credentials\n\n# Outside handler (local testing) — use env vars\n# FALCON_CLIENT_ID and FALCON_CLIENT_SECRET read automatically\n```\n\n## Input Validation\n\n### JSON Schema for Collections\n\nUse strict schemas to prevent data corruption and injection:\n\n```json\n{\n  \"type\": \"object\",\n  \"required\": [\"timestamp\", \"event_type\", \"source\"],\n  \"additionalProperties\": false,\n  \"properties\": {\n    \"event_type\": {\n      \"type\": \"string\",\n      \"enum\": [\"alert\", \"detection\", \"incident\"]\n    },\n    \"source\": {\n      \"type\": \"string\",\n      \"pattern\": \"^[a-zA-Z0-9_-]+$\",\n      \"maxLength\": 50\n    }\n  }\n}\n```\n\n### API Response Sanitization\n\nSanitize CrowdStrike API responses before storing in Collections: remove sensitive fields (`raw_log`, `internal_id`, `system_metadata`), strip script injection, escape HTML entities, and truncate strings. See [references/security-examples.md](references/security-examples.md) for full implementation.\n\n### Function Input Validation\n\nValidate that input is a dict and enforce size limits (e.g., 10KB) to prevent abuse. Return generic error messages — MUST NOT expose stack traces or internal state in responses.\n\n## UI Security\n\n### XSS Prevention\n\n- **React:** Use `DOMPurify.sanitize()` before any `dangerouslySetInnerHTML`. React auto-escapes `{}` expressions.\n- **Vue:** Use `DOMPurify.sanitize()` in a computed property before `v-html`. Vue auto-escapes `{{ }}` expressions.\n\nFor complete React and Vue XSS prevention components, see [references/security-examples.md](references/security-examples.md).\n\n### Content Security Policy\n\nConfigure CSP in `manifest.yml` for UI pages:\n\n```yaml\nui:\n  pages:\n    - name: my-page\n      csp:\n        connect_src:\n          - \"'self'\"\n          - \"https://api.crowdstrike.com\"\n        img_src:\n          - \"'self'\"\n          - \"data:\"\n        script_src:\n          - \"'self'\"\n```\n\n### Iframe Security for Extensions\n\nExtensions run in sandboxed iframes. Validate message origins against Falcon console domains:\n\n```typescript\nconst allowedOrigins = [\n  'https://falcon.crowdstrike.com',\n  'https://falcon.eu-1.crowdstrike.com',\n  'https://falcon.us-gov-1.crowdstrike.com',\n];\n\nwindow.addEventListener('message', (event) => {\n  if (!allowedOrigins.includes(event.origin)) return;\n  // Process event.data\n});\n```\n\nFor the full `SecureConsoleMessaging` class, see [references/security-examples.md](references/security-examples.md).\n\n## Manifest Security Configuration\n\n```yaml\napp:\n  name: \"my-security-app\"\n\noauth_scopes:\n  - \"alerts:read\"\n  - \"hosts:read\"\n\nfunctions:\n  - name: \"process-alerts\"\n    language: \"python\"\n    max_exec_duration_seconds: 30  # Prevent runaway execution\n    max_exec_memory_mb: 128        # Limit resource usage\n\ncollections:\n  - name: \"audit_logs\"\n    ttl: 86400  # Auto-expire sensitive data (24 hours)\n```\n\n## Test Data Security\n\n- Use only RFC 1918 IPs (`192.168.x.x`, `10.x.x.x`) in mock data\n- Use obviously fake hostnames and users (`test-workstation-01`, `test_user`)\n- Validate mock data does not contain production indicators (`crowdstrike.com`, `falcon-`, `prod-`)\n- Test XSS prevention with known attack vectors (`<script>`, `javascript:`, `onerror=`)\n\nSee [references/security-examples.md](references/security-examples.md) for mock data validation and CI/CD security patterns.\n\n## Pre-Deployment Checklist\n\n- [ ] OAuth scopes: minimal required permissions only\n- [ ] Input validation: JSON schemas enforce strict validation\n- [ ] XSS prevention: all user data sanitized before rendering\n- [ ] CSP headers: Content Security Policy configured\n- [ ] Postmessage security: origin validation implemented\n- [ ] Secret management: no hardcoded credentials\n- [ ] Function security: input size limits and timeout controls\n- [ ] Collection security: access controls and data sanitization\n- [ ] Test data: only fake data in tests and development\n- [ ] Error handling: no sensitive data in error messages or logs\n\n## Reading Guide\n\n| Task | Reference |\n|------|-----------|\n| Sanitization, command injection prevention, secure templates | [references/security-examples.md](references/security-examples.md) |\n| CI/CD security pipeline (GitHub Actions) | [references/security-examples.md](references/security-examples.md) |\n| PostMessage class, mock data validation | [references/security-examples.md](references/security-examples.md) |\n| Token lifecycle, antipatterns, manifest security, performance | [references/security-examples.md](references/security-examples.md) |\n"
}

SHA-256: 52e77abb8b1d1274ec7fbf9e10515325d874bceafc4e7a7473f930cd6fb67ea9